Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,840 results · page 32 of 62
- View details
sandbox-claude-insideSkillSecurity
Run Claude Code INSIDE a ca-sandbox box (`--with-claude`). Routed to when the user wants an agent loop running against an isolated, ephemeral sandbox rather than the host. Authenticates via an env-injected CLAUDE_CODE_OAUTH_TOKEN with no host bind of ~/.claude; the image pins the CLI and disables th
Ready to connect★ 145
- View details
security-architectureSkillSecurity
Optional, opt-in STRIDE threat pass for a sensitive feature — invoked deliberately via /threat-model, never forced on ordinary changes. Walks the change's attack surface and security boundaries (governed by ${CLAUDE_PROJECT_DIR}/.codearbiter/security-controls.md), surfaces threats and unmitigated ga
Ready to connect★ 145
- View details
bitbucket-cloudSkillSecurity
Bitbucket Cloud (bitbucket.org) specifics — authenticate with BITBUCKET_TOKEN, use the REST API v2, workspace/repo_slug repositories, and the create_bitbucket_pr tool. Loaded on demand by the bitbucket skill once a Cloud environment is detected.
Ready to connect★ 144
- View details
bitbucket-data-centerSkillSecurity
Bitbucket Data Center (self-hosted Bitbucket Server) specifics — authenticate with BITBUCKET_DATA_CENTER_TOKEN, use the REST API 1.0, PROJECT/repo_slug repositories, scm/ git remotes, and the create_bitbucket_data_center_pr tool. Loaded on demand by the bitbucket skill once a Data Center environment
Ready to connect★ 144
- View details
brandkitSkillSecurity
Premium brand-kit image generation skill for creating high-end brand-guidelines boards, logo systems, identity decks, and visual-world presentations. Trained for minimalist, cinematic, editorial, dark-tech, luxury, cultural, security, gaming, developer-tool, and consumer-app brand systems. Optimized
Ready to connect★ 144
- View details
dependency-risk-auditSkillSecurity
Audit dependencies for licensing, security, and maintenance risk. Use when a senior developer needs risk assessment.
Ready to connect★ 144
- View details
rank-auditSkillSecurity
Full SEO/GEO/AEO/Citability/Content/Performance/Vertical/Security audit with auto-fix. Scans, reports, fixes, and verifies.
Ready to connect★ 144
- View details
security-quick-scanSkillSecurity
Scan code or configuration for common security issues. Use when a mid-level developer needs a quick security pass.
Ready to connect★ 144
- View details
dotnet-dependencySkillSecurity
This skill should be used when investigating .NET project dependencies, understanding why packages are included, listing references, or auditing for outdated/vulnerable packages.
Ready to connect★ 141
- View details
crSkillSecurity
Use when the user invokes /cr, requests a code review, or before committing to verify correctness, security, and quality of new or modified code in the working tree.
Ready to connect★ 140
- View details
ai-safe2SkillSecurity
The Universal Governance, Risk, Compliance (GRC) Operating System with Integrated Security for Agentic AI, Non-Human Identities, and Swarm Governance. AI SAFE² + AI Sovereignty Maturity Model (AISM), NEXUS-A2A Protocol, FORGE-Act, Marshal Plan for AI [Dual License: MIT + CC-BY-SA]
Ready to connect★ 139
- View details
ai-safe2-secure-build-copilotSkillSecurity
Apply AI SAFE2 v3.0 to security architecture reviews, code reviews, compliance mapping, and governance decisions for AI agents, multi-agent systems, RAG pipelines, MCP servers, tool-calling workflows, and AI-enabled automations. Use when the task involves agent autonomy classification, HEAR or CP.9
Ready to connect★ 139
- View details
klaviyo-developerSkillSecurity
Klaviyo API and developer integration expertise. Event tracking, SDKs, webhooks, rate limits, OAuth, catalog sync, and code patterns. Use when the user asks about Klaviyo API, integrating with Klaviyo, tracking events, building custom integrations, webhook handling, or developer implementation. For
Ready to connect★ 139
- View details
openpost-cliSkillSecurity
Operate a running OpenPost instance through the openpost CLI. Use for authentication and profile setup; workspace, account, provider, media, schedule, job, and billing inspection; creating or editing text posts, threads, and format-first publications; scheduling or publishing content; checking lifec
Ready to connect★ 138
- View details
blinkSkillSecurity
Read Blink camera and video-doorbell state, list motion clips, and prepare guarded home-security control requests without exposing Blink credentials.
Ready to connect★ 134
- View details
causal-designSkillSecurity
Design or audit the identification strategy for an observational study. Use when the task concerns estimands, causal assumptions, threats to identification, or defensible research design rather than model implementation.
Ready to connect★ 134
- View details
weakness-scannerSkillSecurity
Identify recurring weak arguments, unsupported assumptions, and vulnerable inference patterns across a literature corpus. Use when stress-testing a body of work rather than reviewing one manuscript. For one paper's argument, use the appropriate paper-review workflow.
Ready to connect★ 134
- View details
evals-initSkillSecurity
Initialize evals/{system}/ directory structure for evaluation system following EDD principles (Standalone). Choose PromptFoo or DeepEval based on tech stack, generate security baseline.
Ready to connect★ 133
- View details
linear-configSkillSecurity
Configure linear-cli - auth (API key + OAuth), workspaces, diagnostics, setup wizard.
Ready to connect★ 133
- View details
sellSkillSecurity
Self-contained SaaS automation — invoke directly, do not decompose. Transforms a Vibes app into a multi-tenant SaaS with subdomain-based tenancy. Adds Pocket ID authentication, subscription gating, and generates a unified app with landing page, tenant routing, and admin dashboard. Use when the user
Ready to connect★ 133
- View details
agent-authenticationSkillSecurity
Agent skill for authentication - invoke with $agent-authentication
Ready to connect★ 132
- View details
agent-security-managerSkillSecurity
Agent skill for security-manager - invoke with $agent-security-manager
Ready to connect★ 132
- View details
agent-v3-security-architectSkillSecurity
Agent skill for v3-security-architect - invoke with $agent-v3-security-architect
Ready to connect★ 132
- View details
vulnhunterSkillSecurity
Security vulnerability detection and variant analysis skill. Use when hunting for dangerous APIs, footgun patterns, error-prone configurations, and vulnerability variants across codebases. Combines sharp edges detection with variant hunting methodology.
Ready to connect★ 128
- View details
zz-code-reconSkillSecurity
Deep architectural context building for security audits. Use when conducting security reviews, building codebase understanding, mapping trust boundaries, or preparing for vulnerability analysis. Inspired by Trail of Bits methodology.
Ready to connect★ 128
- View details
api-designSkillSecurity
Backend API design specialist. Use when building REST/GraphQL APIs, designing endpoints, data models, or backend architecture. Covers RESTful principles, HTTP semantics, error handling, versioning, and OWASP-aligned security.
Ready to connect★ 126
- View details
argentos-security-auditSkillSecurity
Security audit procedures for ArgentOS marketplace packages. Use when scanning packages, reviewing submissions, auditing for prompt injection, checking VirusTotal results, approving marketplace submissions, or when anyone mentions "security scan", "VT scan", "prompt injection", "audit package", "rev
Ready to connect★ 126
- View details
community-requesting-code-reviewSkillSecurity
Pre-commit verification pipeline — static security scan,
Ready to connect★ 126
- View details
evalSkillSecurity
Evaluates code output across 4 axes (functionality/quality/originality/security) and produces a score. Spawns an Evaluator agent to run an independent evaluation. Triggers on: eval, 평가, 품질 점수, 코드 평가, quality score. NOT for: 코드 작성, 구현, 리뷰.
Ready to connect★ 125
- View details
pr-review-expertSkillSecurity
Use when the user asks to review pull requests, analyze code changes, check for security issues in PRs, or assess code quality of diffs.
Ready to connect★ 124
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
54,764 of the 55,196 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.